Back to skill

Security audit

Luis Audio Translator

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local audio-processing tool, but it includes an under-disclosed cleanup option that can recursively delete any writable output directory an agent points it at.

Review this skill before installing if agents may run it autonomously. It should only process local media files, but avoid using the split --clean option until it is constrained to a safe generated directory or requires clear confirmation. Also ensure any FFmpeg, Kugou, or other helper paths configured through environment variables point to trusted local binaries.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/luis_audio_translator.py:271
Finding

Arbitrary Recursive Directory Deletion Through split --clean

Content
View full analysis

Vulnerability Details

File Location: scripts/luis_audio_translator.py, lines 271-274
Vulnerability Type: Unrestricted recursive directory deletion
Risk Level: High

python
output_dir = Path(args.output_dir or input_path.parent / f"{input_path.stem}_分割")
if output_dir.exists() and args.clean:
    shutil.rmtree(output_dir)
output_dir.mkdir(parents=True, exist_ok=True)

Technical Analysis

The split command accepts an arbitrary path through --output-dir. When the --clean option is also supplied, the implementation passes that path directly to shutil.rmtree().

The path is not canonicalized or checked against an approved output boundary. The code also does not verify that the directory was created by this Skill, contains only prior split results, or is safe to remove. There are no protections against selecting a filesystem root, home directory, project directory, input directory, or another unrelated directory.

This creates a destructive path-manipulation vulnerability. Although exploitation requires control over or influence upon the command arguments, Agent-generated command lines may incorporate attacker-controlled instructions or paths. No command injection is required.

Attack Path

  1. An attacker influences the user or Agent to invoke the split operation on a valid media file.

  2. The attacker supplies an existing valuable directory as --output-dir.

  3. The attacker causes the invocation to include --clean, for example:

    text
    python scripts/luis_audio_translator.py split input.mp3 --segment-seconds 300 --format mp3 --output-dir /path/to/valuable-directory --clean
    
  4. The application confirms only that the selected path exists.

  5. Before FFmpeg processing starts, shutil.rmtree(output_dir) recursively deletes the selected directory.

  6. The application recreates an empty directory at the same path and proceeds with the split operation, potentially obscur ...[truncated 597 chars]

Remediation
View remediation

Remediation Suggestions

  1. Avoid recursively deleting a user-selected output directory. Delete only files known to have been generated by a previous split operation.
  2. Resolve the output path with Path.resolve() and reject dangerous targets, including filesystem roots, the user's home directory, the input file's parent directory, the project directory, and other protected locations.
  3. Create a dedicated subdirectory for every split operation rather than cleaning an arbitrary caller-provided directory.
  4. Place a Skill-specific marker file in generated directories and permit cleanup only when that marker is present and valid.
  5. Refuse cleanup if the target path or any relevant path component violates the expected directory policy.
  6. Require explicit interactive confirmation for destructive cleanup when interactive execution is available.
  7. Use a safe cleanup routine that enumerates and validates each expected generated file instead of calling shutil.rmtree() on the entire directory.
  8. Add tests covering dangerous values such as filesystem roots, home directories, relative traversal paths, the input directory, and unrelated pre-existing directories.
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
Do not put user-specific paths in `SKILL.md`. If a machine needs a local engine directory, set an environment variable outside the skill.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
Do not put user-specific paths in `SKILL.md`. If a machine needs a local engine directory, set an environment variable outside the skill.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
Do not put user-specific paths in `SKILL.md`. If a machine needs a local engine directory, set an environment variable outside the skill.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to run local Python scripts, read and write files, inspect environment-configured paths, and invoke shell-accessible tools like FFmpeg/FFprobe, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a trust gap where an agent may grant broader capabilities than necessary, increasing the risk of unintended command execution, access to sensitive local files, or misuse of environment-provided helper binaries.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/kugou_audio_converter.py (reported line 39)May include surrounding context.

python
def run(cmd, print_command=False, cwd=None):
    if print_command:
        print(json.dumps({"command": [str(x) for x in cmd]}, ensure_ascii=False))
    proc = subprocess.run(
        [str(x) for x in cmd],
        cwd=str(cwd) if cwd else None,
        text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/luis_audio_translator.py (reported line 109)May include surrounding context.

python
def run(cmd, print_command=False, cwd=None):
    if print_command:
        print(json.dumps({"command": [str(x) for x in cmd]}, ensure_ascii=False))
    proc = subprocess.run(
        [str(x) for x in cmd],
        cwd=str(cwd) if cwd else None,
        text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/kugou_audio_converter.py (reported line 147)May include surrounding context.

python
if db and db.exists():
            cmd += ["--db", db]
        cmd += [work]
        proc = subprocess.run(
            [str(x) for x in cmd],
            text=True,
            encoding="utf-8",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The display name "Luis Audio Translator" embeds a specific language/locale identity in the skill presentation, but the file provides no indication that users can choose or opt into that language context. Under the policy, language or locale constraints should either be optional or clearly justified.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/luis_audio_translator.py (reported line 169)May include surrounding context.

python
if fmt == "m4r":
        opts += ["-f", "mp4"]
    for key in ("title", "artist", "album", "date", "genre"):
        value = getattr(args, key, None)
        if value:
            opts += ["-metadata", f"{key}={value}"]
    return opts

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script creates the output directory and writes a decoded audio file to disk, but there is no prior confirmation prompt, cautionary comment, or user-facing warning about modifying the filesystem. For a code file, file writes should have some visible disclosure unless clearly covered elsewhere; this file only describes decoding and does not warn about creating directories and writing output files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.